ZeroHour

CVE-2025-12490

large

Authenticated Path Traversal RCE in Netgate pfSense CE Suricata Package

CVSS 3.0
8.8 high
EPSS
20%p97
Published
()
Modified
AI analysis

CVE-2025-12490 is a path traversal flaw (CWE-22) in the Suricata package for Netgate pfSense CE, caused by insufficient validation of a user-supplied path before it is used in file operations. A remote attacker who holds valid low-privilege credentials on the pfSense web interface can submit a crafted path to create arbitrary files on the firewall. Because files are written in the context of root, this can be leveraged for full remote code execution with highest impact on confidentiality, integrity and availability (CVSS 3.0 score 8.8). Only pfSense CE deployments that have the Suricata package installed are affected, and exploitation requires authentication. No public proof-of-concept is known, the flaw is not in CISA's KEV catalog, and it is not yet known to be exploited in the wild, although a high EPSS score (20.1%, 97th percentile) indicates a meaningful chance of exploitation within 30 days.

What to do: Apply the patched Suricata package update via the pfSense Package Manager as soon as Netgate publishes it, and check the ZDI advisory (ZDI-CAN-28085) for the fixed version. Until then, restrict access to the pfSense web interface to trusted management networks and review local accounts, since exploitation requires valid credentials. Check affected firewalls for unexpected root-owned files or new persistence artifacts as a precaution.

Affected
Netgate pfSense CE (Suricata package)
Estimated exposure
large≈tens of thousands of pfSense CE firewalls running the Suricata package (plausibly 10k–100k) — pfSense CE has a very large installed base (Netgate has cited millions of pfSense installations) and public internet scans have shown tens of thousands of exposed pfSense web consoles, with Suricata consistently among the most-installed…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Netgate pfSense CE Suricata Path Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to create arbitrary files on affected installations of Netgate pfSense. Authentication is required to exploit this vulnerability. The specific flaw exists within the Suricata package. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to create files in the context of root. Was ZDI-CAN-28085.

Weakness
CWE-22
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.